Anthropic Caught Secretly Tagging Claude Code Users Bypassing Proxies
Oh, look, another "safety-first" AI darling caught doing digital espionage. Anthropic secretly shipped covert tracking inside Claude Code to tag sneaky developers, proving that nothing says "ethical AI" like hiding spyware in an apostrophe.
A Reddit user named LegitMichel777 dissected the Claude Code binary and discovered a tracking mechanism hidden inside the tool since April 2, 2026. This stealthy telemetry remained active for nearly three months across multiple versions, quietly flagging users who rerouted their API traffic through third-party gateways.
The script sprang to life only when developers configured the ANTHROPIC_BASE_URL environment variable. It scanned system timezones for Shanghai or Urumqi, checked proxies against a hardcoded list of Chinese tech giants like Alibaba and Baidu, and sniffed out keywords of local AI labs like DeepSeek or Moonshot AI.
Instead of sending this data back via a normal, boring API call, the tool used digital steganography to hide the evidence in plain sight. It altered the system prompt "Today's date is" by swapping the standard apostrophe with one of three identical-looking Unicode characters and switching hyphens to slashes in the date string. It is the cryptographic equivalent of wearing a fake mustache to a bank robbery. The list of banned domains itself was obfuscated using Base64 and a basic XOR operation to keep casual snoops away.
Anthropic's engineer Tariq Shihiphar quickly admitted to the tracking, rebranding the sneaky telemetry as a "temporary experiment" aimed at stopping unauthorized resellers and model distillation. He confirmed the code had been purged in version 2.1.197, though critics point out that an actual malicious actor could bypass this entire digital dragnet in five minutes just by changing their timezone and hostname.
The company has been aggressively fighting Chinese tech firms, recently telling the US Senate that Alibaba’s Qwen lab used 25,000 fraudulent accounts and 28.8 million queries to siphon intelligence from Claude.
The irony is delicious: the industry's most vocal champions of AI safety and ethics resorted to the oldest, grimiest malware tricks in the book just to protect their intellectual property. When corporate paranoia collides with high-minded philosophy, the code always reveals who these companies actually are when they think nobody is decompiling their binaries.
Source: Reddit
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.